ai-jail puts AI coding agents such as Claude Code inside a local operating system sandbox. It's for developers who want an agent to work on a project while limiting its access to the rest of their machine. Written in Rust and licensed under GPL-3.0, it runs on Linux and macOS; Windows users need WSL2 with the Linux backend.
The agent can edit the project directory by default, but it gets a separate temporary home. Host credentials and the full shell environment stay outside unless explicitly shared. Network access is off by default, as are GPU, display, Docker and SSH access. Files containing project secrets remain readable unless masked or blocked. A read-only lockdown mode supports work that shouldn't modify files.
Network permissions can be limited to named hosts instead of allowing unrestricted access. For compatible HTTP clients, a proxy can keep real API keys outside the sandbox and insert them only into requests to their assigned host. This substitution doesn't work inside opaque HTTPS CONNECT tunnels, and the supervising proxy sees the plaintext requests it handles. Optional local audit logs record launches and filtered network decisions, with a separate integrity check.
Linux uses bubblewrap with namespace isolation, plus Landlock, seccomp and resource limits where available. macOS relies on Apple's deprecated sandbox-exec interface. By default, repository-level policy can tighten restrictions but can't grant broader host access. Neither backend covers kernel or driver vulnerabilities, terminal emulator vulnerabilities, or every IPC and side-channel risk; hostile code still calls for a disposable VM.
Claim this page and we'll verify you by hand. ai-jail gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find ai-jail?Promote it
Something wrong or outdated on this page?
667Updated 2 days agoApache-2.0
macOS · Linux#Agent Skills#Browser automation#Code execution
h5i is a local, open-source toolkit that gives your AI agent browser automation and direct HTTP control for testing web applications you own or are authorized to assess. It's for teams that want an agent to investigate security flaws, with recorded evidence they can review, even without a dedicated security specialist.
2.2KUpdated 3 months agoApache-2.0
macOS · Linux#Code execution#Guardrails
Gondolin is a local sandbox for developers whose AI agents execute generated code and need access to files or external APIs. It runs that code inside disposable Linux micro-VMs on macOS or Linux, while the host controls network access, credentials and filesystem behavior. It's open source under Apache 2.0.
814Updated 18 hours ago
macOS · Linux · Docker · Web#Agent Client Protocol#Code execution#Git integration
Helix is a paid, self-hosted platform for engineering teams running coding agents in parallel. Each task gets an isolated Linux desktop with an editor, browser and terminal, so agents can build and test applications while teammates watch or take control through their browsers.
4.3KUpdated 6 hours agoApache-2.0
macOS · Windows · Linux#Code execution#Guardrails#Human approval
13.7KUpdated 10 hours agoApache-2.0
macOS · Windows · Linux · Docker#Agent Skills#Code execution#Guardrails
OpenShell is a self-hosted runtime for teams running autonomous AI agents that need access to files, APIs and credentials. It runs agents in sandboxes with kernel-level isolation and explicit access policies. It's open source under Apache 2.0 and supports Linux and macOS on Apple Silicon, with Docker, Podman or host virtualization.
1.3KUpdated 4 weeks agoMIT
macOS · Windows · Linux#Code execution#Guardrails#MCP
nono is an open-source security runtime for people running terminal AI agents on their own machines or servers. It limits what an agent and each tool it calls can access, with boundaries enforced by the operating system. It runs on macOS, Linux and Windows through WSL2, without requiring a container, VM or daemon.
Reverify is a local verification toolkit for developers and reverse engineers who use AI to analyze binaries or rewrite code. It checks a model's claims against the actual file or executed behavior, then returns a verdict with evidence. The Python project is open source under the MIT license and runs on Linux, Windows and macOS as a CLI or MCP server.